CERT-In Issues High-Severity Apple Security Alert: iPhone, iPad and Mac Users Must Update
CERT-In has warned iPhone, iPad and Mac users about CVE-2026-86950, a flaw 'being actively exploited' in a sophisticated attack on targeted individuals. Users on iOS and iPadOS older than 26.7.1 are advised to update now.
Apple users in India have been asked to update their devices without delay after the Indian Computer Emergency Response Team (CERT-In) issued a high-severity advisory on October 1, flagging a security flaw in iOS, iPadOS and macOS that could let an attacker run malicious code on an affected device. The government-backed cyber security agency has identified the vulnerability as CVE-2026-86950 and said it is already being used in the wild, which makes the warning more urgent than a routine patch notice. Anyone still running an older software version on an iPhone, iPad or Mac is considered exposed.
Apple has also acknowledged that the bug may have been used in real attacks, and has already pushed out fixes for iPhones, iPads and Macs.
What CERT-In Has Said About CVE-2026-86950
In its advisory, CERT-In said: "This vulnerability (CVE-2026-86950) is being actively exploited in an extremely sophisticated attack against specific targeted individuals on affected system. Users are strongly advised to apply the latest patches immediately."Â iOS 27, iPadOS 27, macOS 27 Golden Gate and watchOS 27 Support List: Here's What Devices Make the Cut.
Apple's Statement on the Flaw
Apple, in its own disclosure, said: "Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27."Â Apple iOS 27 With Siri AI And Liquid Glass Design Released; Check List of Supported Devices, Features.
Which iPhones, iPads and Macs Are Affected?
The advisory covers the following software versions:
- iPhone and iPad: iOS and iPadOS versions older than 26.7.1
- Mac: macOS Tahoe versions older than 26.7.1
- Mac: macOS Sequoia versions older than 15.8.1
Apple released iOS 26.7.1 and iPadOS 26.7.1 on September 28. The iOS update is available for the iPhone 11 and later, along with several supported iPad models. For Macs, the fix has arrived through macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1.
How Could the Attack Affect Your Device?
The flaw can be triggered when a user is tricked into opening a specially crafted malicious file. If the attempt succeeds, the attacker could run unauthorised code on the device and potentially get access to sensitive information.
Users should therefore stay careful with unknown files and attachments received over messages, emails or any other source.
How to Update Your Apple Device
On an iPhone or iPad, open Settings > General > Software Update and install the latest available version.
On a Mac, open System Settings > General > Software Update and check for the latest version available for your device.
(The above story first appeared on LatestLY on Oct 02, 2026 10:12 AM IST. For more news and updates on politics, world, sports, entertainment and lifestyle, log on to our website latestly.com).